Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Songs created by AI banned from Australia’s music charts

    August 25, 2026

    UK drone factories may face attacks from ‘unknown sources’ says Kremlin advisor

    August 25, 2026

    SEC subpoenas Wall Street banks over Situational Awareness

    August 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Songs created by AI banned from Australia’s music charts
    • UK drone factories may face attacks from ‘unknown sources’ says Kremlin advisor
    • SEC subpoenas Wall Street banks over Situational Awareness
    • India’s Airbound bags $37M to take on trucks with rocket-like drones
    • 91 Vulnerabilities Patched in Spring Application Framework
    • Ledger patched an Ethereum app bug that could show one transaction and sign another
    • Scientists just imaged the hidden quantum shape of a molecule
    • Wind energy surplus fuels unregulated data centers in Brazil’s dry land
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    91 Vulnerabilities Patched in Spring Application Framework

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 25, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The developers of Broadcom’s Spring application development framework last week announced the release of updates that patch 91 vulnerabilities. 

    Spring is an open source application framework for the Java platform that simplifies the creation of enterprise applications through features such as dependency injection, aspect-oriented programming, and modular support for web, data, and messaging architectures. After years under VMware’s stewardship, it transitioned to Broadcom following its acquisition of VMware.

    A single vulnerability has been assigned a critical severity rating: CVE-2026-59270. It affects Spring Security’s embedded UnboundID LDAP server and could allow an attacker to authenticate and modify entries in the in-memory directory. 

    Over a dozen vulnerabilities have been classified as high severity. They can be exploited for XSS attacks, information disclosure, remote code execution, DoS attacks, security bypasses, and unauthorized access.

    The remaining vulnerabilities have medium and low severity ratings.

    Cybersecurity firm Sonatype has analyzed the patches and found that they impact more than 200,000 software components. The security flaws affect projects such as Spring Security, Spring AI, Cloud Config, Data REST, Integration, Reactor Core, Reactor Netty, AMQP, and Batch.

    Advertisement. Scroll to continue reading.

    Sonatype has highlighted two vulnerabilities: CVE-2026-59285, which it describes as a critical remote code execution issue in Spring for GraphQL, and CVE-2026-59318, a medium-severity issue in Spring AI’s tool-calling functionality that can allow privilege escalation through prompt injection. 

    The surge in Spring vulnerabilities is unsurprisingly driven by Broadcom’s use of AI.

    More than 200 vulnerabilities have been patched to date this year, compared to only 16 in 2025 and 22 in 2024. 

    Spring vulnerabilities can be useful to threat actors, and they have been exploited in the wild, including the notorious Spring4Shell. CISA’s KEV catalog currently includes several such vulnerabilities. 

    Open source projects are advised to review the latest Spring patches and apply them.

    Related: Critical Isolated-vm Vulnerability Leads to RCE on Host

    Related: CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

    Related: Hackers Target Zimbra Servers in Active Exploitation Campaign

    Application Framework Patched spring Vulnerabilities
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Ledger patched an Ethereum app bug that could show one transaction and sign another

    Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts

    Foul Language: WordlistLoader Disguises Malware as Ordinary Text

    Hired for One Job, Judged on Another: The CISO’s Real Problem

    Hackers target WordPress sites in miniOrange auth bypass attacks

    Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Songs created by AI banned from Australia’s music charts

    August 25, 2026

    UK drone factories may face attacks from ‘unknown sources’ says Kremlin advisor

    August 25, 2026

    SEC subpoenas Wall Street banks over Situational Awareness

    August 25, 2026

    India’s Airbound bags $37M to take on trucks with rocket-like drones

    August 25, 2026
    Latest Posts

    The Doctor and His Diary: What Fauci’s Innermost Musings Reveal

    July 29, 2026

    Iran Considered Retaliatory Strike on Ukrainian Seaport

    July 29, 2026

    The French presidential candidate who wants to blow up the Franco-German engine – POLITICO

    July 29, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Songs created by AI banned from Australia’s music charts

    August 25, 2026

    UK drone factories may face attacks from ‘unknown sources’ says Kremlin advisor

    August 25, 2026

    SEC subpoenas Wall Street banks over Situational Awareness

    August 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.